Question: Analyze the following script. Which type of Antivirus Solution is being disabled when the script is executed? Import - Module - DisableNameChecking $PSScriptRoot .
Analyze the following script. Which type of Antivirus Solution is being disabled when the script is executed?
ImportModule DisableNameChecking $PSScriptRootlibNewFolderForced.psm ImportModule DisableNameChecking $PSScriptRootlibtakeown.psm WriteOutput "Elevating priviledges for this process" do until ElevatePrivileges SeTakeOwnershipPrivilege $tasks @MicrosoftWindowsWindows DefenderWindows Defender Cache Maintenance" MicrosoftWindowsWindows DefenderWindows Defender Cleanup" MicrosoftWindowsWindows DefenderWindows Defender Scheduled Scan" MicrosoftWindowsWindows DefenderWindows Defender Verification" foreach $task in $tasks $parts $task.split $name $parts $path $parts$parts.lengthjoin WriteOutput "Trying to disable scheduled task $name" DisableScheduledTask TaskName $name" TaskPath $path" WriteOutput "Disabling Antivirus Software via Group Policies" NewFolderForced Path HKLM:SOFTWAREWowNodePoliciesMicrosoftWindows Defender" SetItemProperty Path HKLM:SOFTWAREWowNodePoliciesMicrosoftWindows Defender" "DisableAntiSpyware" SetItemProperty Path HKLM:SOFTWAREWowNodePoliciesMicrosoftWindows Defender" "DisableRoutinelyTakingAction" NewFolderForced Path HKLM:SOFTWAREWowNodePoliciesMicrosoftWindows DefenderRealTime Protection" SetItemProperty Path HKLM:SOFTWAREWowNodePoliciesMicrosoftWindows DefenderRealTime Protection" "DisableRealtimeMonitoring" WriteOutput "Disabling Antivirus Services" TakeownRegistryHKEYLOCALMACHINESYSTEMCurrentControlSetServicesWinDefend SetItemProperty Path HKLM:SYSTEMCurrentControlSetServicesWinDefend "Start" SetItemProperty Path HKLM:SYSTEMCurrentControlSetServicesWinDefend "AutorunsDisabled" SetItemProperty Path HKLM:SYSTEMCurrentControlSetServicesWdNisSvc "Start" SetItemProperty Path HKLM:SYSTEMCurrentControlSetServicesWdNisSvc "AutorunsDisabled" SetItemProperty Path HKLM:SYSTEMCurrentControlSetServicesSense "Start" SetItemProperty Path HKLM:SYSTEMCurrentControlSetServicesSense "AutorunsDisabled" WriteOutput "Removing Windows Defender context menu item" SetItem HKLM:SOFTWAREClassesCLSIDABDAAFADAInprocServer WriteOutput "Removing Windows Defender GUI tray from autorun" RemoveItemProperty HKLM:SOFTWAREMicrosoftWindowsCurrentVersionRun "WindowsDefender" ea
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
